Contains Nonbinding Recommendations
25
a security compromise could impact the safety or effectiveness of the device. These security use 
cases should cover various operational states of elements in the medical device system (e.g., 
power on, standby, transition states) and assess clinical functionality states of the medical device 
system (e.g., programming, alarming, delivering therapy, send/receive data, reporting diagnostic 
results). 
The number of security use cases that should be assessed will scale with the cybersecurity 
complexity and risk of the device. Each view should include detailed information as 
recommended in Appendix 2. For use cases identified that share the same security assessment, 
the associated diagrams and explanatory text can describe the multiple use cases covered by the 
view in lieu of providing duplicative information in multiple places. For example, programming 
commands and sending/receiving device data may share the same communication protocol and 
therefore may not exhibit differences between the security views for both scenarios, despite 
having different clinical risk assessments.
C.
Cybersecurity Testing 
As with other areas of product development, testing is used to demonstrate the effectiveness of 
design and development activities. While software development and cybersecurity are closely 
related disciplines, cybersecurity controls require testing beyond standard software verification 
and validation activities to demonstrate the effectiveness of the controls in a proper security 
context to therefore demonstrate that the device has a reasonable assurance of safety and 
effectiveness. 
Under Subclause 7.3.6 of ISO 13485, a manufacturer must establish and maintain procedures for 
verifying the device design. Such verification shall confirm that the design output meets the 
design input requirements. Under Subclause 7.3.7, a manufacturer must establish and maintain 
procedures for validating its device design. FDA recommends verification and validation include 
sufficient testing performed by the manufacturer on the cybersecurity of the medical device 
system through which the manufacturer verifies and validates their inputs and outputs, as 
appropriate. 
Security testing documentation and any associated reports or assessments should be submitted in 
the premarket submission. FDA recommends that the following types of testing, among others, 
be considered for inclusion in the submission:
·
Security requirements; 
·
Manufacturers should provide evidence that each design input requirement was 
implemented successfully.
·
Manufacturers should provide evidence of their boundary analysis and rationale 
for their boundary assumptions.
·
Threat mitigation; 
·
Manufacturers should provide details and evidence of testing that demonstrates 
effective risk control measures according to the threat models provided in the 
global system, multi-patient harm, updatability and patchability, and security use 
case views.
